CRITICAL 9.8 PyPI

Improper Verification of Cryptographic Signature in starkbank-ecdsa

GHSA-92vm-mxjf-jqf3 · CVE-2021-43572 · PYSEC-2021-426

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The verify function in the Stark Bank Python ECDSA library (starkbank-ecdsa) 2.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

Ready to move

Start Securing

Free, no credit card | First findings in minutes